{"id":"CVE-2026-40068","aliases":["GHSA-q5hj-mxqh-vv77"],"url":"https://o3.security/vulnerability/CVE-2026-40068","summary":"Claude Code arbitrary code execution via git worktree commondir trust dialog bypass","details":"In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious repository with a commondir file pointing to a path the victim had previously trusted, causing Claude Code to bypass its trust confirmation dialog and immediately execute hooks defined in `.claude/settings.json`. Exploitation requires the victim to clone the malicious repository and run Claude Code within it, and the attacker must know or guess a path the victim had already trusted. This issue has been fixed in version 2.1.84.","published":"2026-05-05T20:52:26.089Z","modified":"2026-08-07T11:31:28.881780683Z","cvss":null,"epss":{"score":0.00281,"percentile":0.20324,"asOf":"2026-08-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@anthropic-ai/claude-code","fixedVersion":"2.1.84"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/40xxx/CVE-2026-40068.json"},{"type":"ADVISORY","url":"https://github.com/anthropics/claude-code/security/advisories/GHSA-q5hj-mxqh-vv77"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-40068"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-07T11:31:28.881780683Z"}}